PI Nexus+ / Reference
Ports and Firewall
This reference lists every network connection PI Nexus+ makes, so you can request firewall rules before installation. Plan the Deployment in the Installation Guide shows the same connections as a diagram.
Overview
This reference lists every network connection PI Nexus+ makes, so you can request firewall rules before installation. Plan the Deployment in the Installation Guide shows the same connections as a diagram.
Inbound
| To | Port | From | Used for |
|---|---|---|---|
| Web server | TCP 5139 (installer property IISPORT) | Users' browsers | The PI Nexus+ site over HTTP |
| Web server | TCP 443 or your port | Users' browsers | Only if you add an HTTPS binding in IIS yourself (see Use HTTPS in the Installation Guide) |
The scanner server accepts no inbound connections. The web server and the scanner server never connect to each other.
Outbound from both servers
On a single server, both columns are the same machine. On a split deployment, open each path from both servers unless the last column says otherwise.
| To | Port | Needed when | Used by |
|---|---|---|---|
| SQL Server hosting the PI Nexus+ database | TCP 1433, or the instance's port; UDP 1434 for SQL Server Browser with a named instance | Always | Both |
| PI Data Archive, every collective member | TCP 5450 | Always | Both (the web server for Test, discovery and compression changes; the scanner for scans and runtime polls) |
| AF Server | TCP 5457 | Always | Both |
| SQL Server hosting the PI Vision database | TCP 1433, or the instance's port | PI Vision inventory is used | Both (the web server for Test) |
| SMTP server | TCP 25 by default; as set under Admin > Notifications | Emails are used | Both (the web server for the test email) |
| Domain controllers | Standard Active Directory ports | Always: Windows sign-in, account and group lookups | Both |
| Identity server used by OpenID Connect targets | TCP 443, or the port the identity server publishes (AVEVA Identity Manager commonly uses 444) | A PI Data Archive or AF Server target uses OpenID Connect | Both |
PI Vision inventory reads the PI Vision database only. The PI Vision web address is used for links in users' browsers and for host monitoring availability checks, not for scanning.
Outbound from the scanner server only
| To | Port | Used for |
|---|---|---|
| Monitored hosts | TCP 5985 (WinRM over HTTP) | Host monitoring with the scanner service account |
| Monitored hosts outside the domain | TCP 5986 (WinRM over HTTPS) | Host monitoring with a credential profile |
| SQL Servers on monitored hosts | TCP 1433 or the instance's port | Optional SQL Server readings |
| Any host | As configured | Availability checks you add |
All host monitoring ports are listed under Ports in Host Monitoring Reference.
Local ports on the PI Nexus+ servers
| Item | Default | Change with |
|---|---|---|
| IIS site binding | http, all addresses, port 5139 | IISPORT at installation, or IIS Manager afterwards |
| Start menu and desktop shortcuts | http://localhost:<IISPORT>/ | Follow IISPORT; the port is stored in HKLM\Software\Software Athlete\PI Nexus+\IisPort |
Note: An upgrade or repair keeps your IIS bindings. Adding the web application again in a maintenance installation recreates the site's binding on IISPORT and removes others, such as an HTTPS binding you added.
